NIST SP 800-53 Rev 5 LOW
NIST SP 800-53 Rev 5 LOW baseline. Federal Information Security Management Act controls for systems at LOW impact level.
NIST SP 800-53 Rev 5 LOW is a compliance framework from United States with 20 domains and 173 controls that map to 283 other frameworks. The largest domains are PM Program Management (32 controls), AC Access Control (11 controls), AU Audit and Accountability (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
AC Access Control
| Code | Title |
|---|---|
| AC-1 | Policy and Procedures |
| AC-14 | Permitted Actions Without Identification or Authentication |
| AC-17 | Remote Access |
| AC-18 | Wireless Access |
| AC-19 | Access Control for Mobile Devices |
| AC-2 | Account Management |
| AC-20 | Use of External Systems |
| AC-22 | Publicly Accessible Content |
| AC-3 | Access Enforcement |
| AC-7 | Unsuccessful Logon Attempts |
| AC-8 | System Use Notification |
AT Awareness and Training
AU Audit and Accountability
| Code | Title |
|---|---|
| AU-1 | Policy and Procedures |
| AU-11 | Audit Record Retention |
| AU-12 | Audit Record Generation |
| AU-2 | Event Logging |
| AU-3 | Content of Audit Records |
| AU-4 | Audit Log Storage Capacity |
| AU-5 | Response to Audit Logging Process Failures |
| AU-6 | Audit Record Review, Analysis, and Reporting |
| AU-8 | Time Stamps |
| AU-9 | Protection of Audit Information |
CA Assessment, Authorization, and Monitoring
| Code | Title |
|---|---|
| CA-1 | Policy and Procedures |
| CA-2 | Control Assessments |
| CA-3 | Information Exchange |
| CA-5 | Plan of Action and Milestones |
| CA-6 | Authorization |
| CA-7 | Continuous Monitoring |
| CA-7(4) | Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring |
| CA-9 | Internal System Connections |
CM Configuration Management
| Code | Title |
|---|---|
| CM-1 | Policy and Procedures |
| CM-10 | Software Usage Restrictions |
| CM-11 | User-Installed Software |
| CM-2 | Baseline Configuration |
| CM-4 | Impact Analyses |
| CM-5 | Access Restrictions for Change |
| CM-6 | Configuration Settings |
| CM-7 | Least Functionality |
| CM-8 | System Component Inventory |
CP Contingency Planning
IA Identification and Authentication
| Code | Title |
|---|---|
| IA-1 | Policy and Procedures |
| IA-11 | Re-Authentication |
| IA-2 | Identification and Authentication (Organizational Users) |
| IA-4 | Identifier Management |
| IA-5 | Authenticator Management |
| IA-6 | Authentication Feedback |
| IA-7 | Cryptographic Module Authentication |
| IA-8 | Identification and Authentication (Non-Organizational Users) |
IR Incident Response
MA Maintenance
MP Media Protection
PE Physical and Environmental Protection
| Code | Title |
|---|---|
| PE-1 | Policy and Procedures |
| PE-12 | Emergency Lighting |
| PE-13 | Fire Protection |
| PE-14 | Environmental Controls |
| PE-15 | Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel |
| PE-16 | Delivery and Removal |
| PE-2 | Physical Access Authorizations |
| PE-3 | Physical Access Control |
| PE-6 | Monitoring Physical Access |
| PE-8 | Visitor Access Records |
PL Planning
| Code | Title |
|---|---|
| PL-1 | Policy and Procedures |
| PL-10 | Baseline Selection. Select a control baseline for the system |
| PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions |
| PL-2 | System Security and Privacy Plans |
| PL-4 | Rules of Behavior |
PM Program Management
| Code | Title |
|---|---|
| PM-1 | Information Security Program Plan |
| PM-10 | Authorization Process |
| PM-11 | Mission and Business Process Definition |
| PM-12 | Insider Threat Program |
| PM-13 | Security and Privacy Workforce |
| PM-14 | Testing, Training, and Monitoring |
| PM-15 | Security and Privacy Groups and Associations |
| PM-16 | Threat Awareness Program |
| PM-17 | Protecting CUI on External Systems |
| PM-18 | Privacy Program Plan |
| PM-19 | Privacy Program Leadership Role |
| PM-2 | Information Security Program Leadership Role |
| PM-20 | Dissemination of Privacy Program Information |
| PM-21 | Accounting of Disclosures |
| PM-22 | Personally Identifiable Information Quality Management |
| PM-23 | Data Governance Body |
| PM-24 | Data Integrity Board |
| PM-25 | Minimization of PII Used in Testing, Training, and Research |
| PM-26 | Complaint Management |
| PM-27 | Privacy Reporting |
| PM-28 | Risk Framing |
| PM-29 | Risk Management Program Leadership Roles |
| PM-3 | Information Security and Privacy Resources |
| PM-30 | Supply Chain Risk Management Strategy |
| PM-31 | Continuous Monitoring Strategy |
| PM-32 | Purposing |
| PM-4 | Plan of Action and Milestones Process |
| PM-5 | System Inventory |
| PM-6 | Measures of Performance |
| PM-7 | Enterprise Architecture |
| PM-8 | Critical Infrastructure Plan |
| PM-9 | Risk Management Strategy |
PS Personnel Security
| Code | Title |
|---|---|
| PS-1 | Policy and Procedures |
| PS-2 | Position Risk Designation |
| PS-3 | Personnel Screening |
| PS-4 | Personnel Termination |
| PS-5 | Personnel Transfer |
| PS-6 | Access Agreements |
| PS-7 | External Personnel Security |
| PS-8 | Personnel Sanctions |
| PS-9 | Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions |
PT PII Processing and Transparency
| Code | Title |
|---|---|
| PT-1 | Policy and Procedures |
| PT-2 | Authority to Process PII |
| PT-3 | PII Processing Purposes |
| PT-4 | Consent |
| PT-5 | Privacy Notice |
| PT-6 | System of Records Notice |
| PT-7 | Specific Categories of PII |
| PT-8 | Computer Matching Requirements |
RA Risk Assessment
SA System and Services Acquisition
| Code | Title |
|---|---|
| SA-1 | Policy and Procedures |
| SA-2 | Allocation of Resources |
| SA-22 | Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support |
| SA-3 | System Development Life Cycle |
| SA-4 | Acquisition Process |
| SA-5 | System Documentation |
| SA-8 | Security and Privacy Engineering Principles |
| SA-9 | External System Services |
SC System and Communications Protection
| Code | Title |
|---|---|
| SC-1 | Policy and Procedures |
| SC-12 | Cryptographic Key Establishment and Management |
| SC-13 | Cryptographic Protection |
| SC-15 | Collaborative Computing Devices and Applications |
| SC-20 | Secure Name/Address Resolution Service (Authoritative) |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service |
| SC-39 | Process Isolation |
| SC-5 | Denial-of-Service Protection |
| SC-7 | Boundary Protection |
SI System and Information Integrity
SR Supply Chain Risk Management
| Code | Title |
|---|---|
| SR-1 | Policy and Procedures (SR-1) |
| SR-10 | Inspection of Systems or Components (SR-10) |
| SR-11 | Component Authenticity (SR-11) |
| SR-12 | Component Disposal (SR-12) |
| SR-2 | Supply Chain Risk Management Plan (SR-2) |
| SR-3 | Supply Chain Controls and Processes (SR-3) |
| SR-5 | Acquisition Strategies, Tools, and Methods (SR-5) |
| SR-8 | Notification Agreements (SR-8) |
Your Compliance Coverage
If you comply with NIST SP 800-53 Rev 5 LOW, you already cover:
NIST SP 800-53 Rev 5
77%
133 controls mapped
Compare →ISO 27002:2022
76%
132 controls mapped
Compare →SOC 2
74%
128 controls mapped
Compare →+ 280 more: ISO 27001:2022 (71%), PCI DSS 4.0 (68%)
See all 283 mapped frameworks ↓Maps to 283 other frameworks
What is NIST SP 800-53 Rev 5 LOW and who does it apply to?
NIST SP 800-53 Rev 5 LOW is a compliance framework from United States with 20 domains and 173 controls. NIST SP 800-53 Rev 5 LOW baseline. Federal Information Security Management Act controls for systems at LOW impact level. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-53 Rev 5 LOW actually require?
NIST SP 800-53 Rev 5 LOW has 173 controls organised across 20 domains. The largest domains are PM Program Management (32 controls), AC Access Control (11 controls), AU Audit and Accountability (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-53 Rev 5 LOW do I already cover?
NIST SP 800-53 Rev 5 LOW maps to 283 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (77% coverage), ISO 27002:2022 (76% coverage), SOC 2 (74% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-53 Rev 5 LOW?
Start your NIST SP 800-53 Rev 5 LOW compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53 Rev 5 LOW requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 173 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required